An attacker drained nearly 200,000 XRP tokens from the Coreum bridge in 97 minutes on August 9, exploiting a validation gap in the relayer software rather than any weakness in the XRP Ledger.
The bridge halted operations as XRP slid below $1 amid broader market caution.
What Actually Went Wrong on the Bridge
A blockchain bridge is an infrastructure that connects two separate networks. This allows users to move value between chains that cannot communicate directly. Relayers monitor both sides and authorize transfers.
Coreum Bridge lets users lock XRP on XRPL and receive an equivalent bridged version on the Coreum blockchain, which they can use in Coreum apps and later bridge back to XRPL.
So, how did the hack happen? The numbers tell a precise story. The bridge account held roughly 200,410 XRP before the incident and began releasing funds at 19:16 UTC.
Over 97 minutes, the account executed 94 payments totaling 199,916.3 XRP to two newly created wallets, leaving just 493.5 XRP behind.
Follow us on X to get the latest news as it happens.
Every transfer carried a valid authorization. A quorum of 17 out of 28 relayer keys signed each outgoing payment through the multi-signature process. Early social media explanations proved wrong. Warnings blamed rippling and the DefaultRipple flag, though native XRP cannot ripple because it has no issuer or trust lines.
The actual cause sat in the code. Relayers monitor XRP Ledger transactions and submit attestations whenever they detect payments carrying a Coreum-recipient memo.
One check was missing entirely. The software never verified that the payment destination was the bridge itself before crediting the corresponding balance. That omission opened the door.
Transfers between wallets controlled by the attacker were treated as genuine deposits, generating credits that later funded withdrawals of real XRP.
Why the XRP Ledger Was Never at Risk
The execution followed a pattern. Small probe transfers doubled in size before a steady stream of payouts averaging roughly 1,695 XRP every 50 seconds. Laundering began immediately. The receiving wallets forwarded most of the funds, complicating efforts to trace where the proceeds ultimately landed.
An important distinction deserves emphasis. No private keys were compromised, and the multi-signature process functioned exactly as designed, only on flawed evidence.
The XRP Ledger itself remained fully secure. The incident did not affect any of its core protocols, consensus mechanisms, or native transaction handling. Coreum suspended the bridge pending repairs.
Any restart will require destination-address verification, the check whose absence enabled the entire sequence.
An official post-mortem remains pending. Until it arrives, the full timeline and remediation plan stay incomplete for affected users.
XRP traded below $1 on August 11, down roughly 3.30% in the last 24 hours, according to BeInCrypto data.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights.









